Windows Server Update Hardening for Jan.13 Update

 



Microsoft is hardening a Windows Server component.


The focus is on Windows Deployment Services (WDS), which supports “hands-free deployment” using an Unattend.xml (Answer file) for automated installations. A vulnerability (CVE-2026-0386) was discovered that could allow attackers to intercept this file over insecure channels, leading to remote code execution (RCE) and credential theft.

Key Points:

  • Patch Tuesday Update (KB5074109) introduced the first phase of changes on January 13, 2026.
  • Microsoft will phase out hands-free deployment over insecure connections:
    • Currently still supported but discouraged.
    • IT admins can disable it via registry keys now.
    • By April 2026, hands-free deployment will be blocked by default unless explicitly re-enabled.
  • Microsoft warns that re-enabling this feature after April will be considered insecure.
  • Additional event logs are being added to help admins monitor deployment configurations.
  • Despite the active vulnerability, Microsoft is not immediately disabling insecure configurations but may do so later.
  • IT admins should review guidance and prepare alternatives for deployment methods.

Popular posts from this blog

WSUS CVE-2025-59287 Mitigation

CVE-2025-58034 Fortinet Warnings and Mitigation

Cloud Infrastructures are Having a Bad Week